Commit Graph

153 Commits

Author SHA1 Message Date
0xACAB
3fa021d147
Add Conftest. 2021-05-22 04:48:49 -04:00
0xACAB
592af5eecc
Add Grafeas, Notary to supply chain security section. 2021-05-18 18:12:09 -04:00
fabacab
8507439733
Add see also link for Kubernetes section. 2021-05-18 10:14:13 -04:00
0xACAB
8487273304
Add "Supply chain security" section with helm-gpg tool. 2021-05-17 20:27:50 -04:00
fabacab
977fde1673
Add helm-secrets plugin. 2021-05-15 18:05:57 -04:00
fabacab
4193eb20a3
Add Teleport unified access plane. 2021-05-09 15:13:30 -04:00
fabacab
2e4bbd3227
Add Kyverno and k-rail policy enforcement tools to Kubernetes section. 2021-05-04 09:45:34 -04:00
0xACAB
f5fcc4abe4
Add kubernetes-event-exporter. 2021-04-26 01:31:39 -04:00
fabacab
8732bf8815
Fix typo. 2021-04-25 23:37:05 -04:00
fabacab
bc8830b0d7
Fix typo. 2021-04-11 00:06:04 -04:00
fabacab
55a49d8bf8
Link to related section. 2021-04-10 14:26:57 -04:00
fabacab
672139458d
Add certificate-expiry-monitor to Kubernetes section. 2021-04-10 14:19:56 -04:00
fabacab
351c2fabb4
Generalize tracing section to monitoring, add Prometheus, Cortex. 2021-04-10 14:17:29 -04:00
0xACAB
48b09a5182
Add IPFire. 2021-04-04 11:22:33 -04:00
0xACAB
bee36e7121
Add see also link. 2021-03-29 11:28:44 -04:00
fabacab
1b0ad1dae3
Add service meshes, tracing tools, sections. 2021-03-29 11:21:21 -04:00
fabacab
40caf1abdc
Add GlobaLeaks, SecureDrop whistleblower submission systems. 2021-03-27 14:51:59 -04:00
0xACAB
465760cf0a
Fix formatting typo. 2021-03-27 10:31:52 -04:00
0xACAB
2886281f34
Add Qubes OS. 2021-03-27 10:30:48 -04:00
fabacab
2bc46be60a
Add kube-forensics. 2021-03-26 22:44:20 -04:00
fabacab
837ac32a40
Add Dangerzone malware neutering sandbox. 2021-03-16 01:26:31 -04:00
fabacab
548b2bdd5b
Add ESET's Malware IOCs. 2021-03-14 14:26:03 -04:00
fabacab
f47ab5a124
Add Bubblewrap sandboxing utility. 2021-03-06 11:47:15 -05:00
fabacab
741d8e9905
Add Kubernetes sub-section to "Cloud platform security" section.
Adds KubeSec, Polaris, and kube-hunter projects.
2021-02-06 08:32:17 -05:00
fabacab
a70e0cb5fa
Add Open Source Vulnerabilities. 2021-02-06 07:34:01 -05:00
fabacab
64014e0268
Move Bunkerized-nginx to new section, fix link for PlumHound. 2021-01-01 14:54:32 -05:00
0xACAB
57f655d213
Merge pull request #13 from bunkerity/patch-1
Add bunkerized-nginx to "Network perimeter defenses"
2021-01-01 14:44:10 -05:00
Bunkerity
37262d9688
Add bunkerized-nginx to "Network perimeter defenses"
nginx Docker image secure by default.

Avoid the hassle of following security best practices each time you need a web server or reverse proxy. Bunkerized-nginx provides generic security configs, settings and tools so you don't need to do it yourself.

Non-exhaustive list of features :
- HTTPS support with transparent Let's Encrypt automation
- State-of-the-art web security : HTTP security headers, prevent leaks, TLS hardening, ...
- Integrated ModSecurity WAF with the OWASP Core Rule Set
- Automatic ban of strange behaviors with fail2ban
- Antibot challenge through cookie, javascript, captcha or recaptcha v3
- Block TOR, proxies, bad user-agents, countries, ...
- Block known bad IP with DNSBL and CrowdSec
- Prevent bruteforce attacks with rate limiting
- Detect bad files with ClamAV
- Easy to configure with environment variables or web UI
- Automatic configuration with container labels

More info about bunkerized-nginx at https://github.com/bunkerity/bunkerized-nginx.
2021-01-01 15:29:07 +01:00
0xACAB
a042fb0e4a
Add Sunburst countermeasures IoC collection. 2020-12-14 02:05:07 -05:00
fabacab
1588e675e4
Add Atheris. 2020-12-12 00:39:51 -05:00
fabacab
e27f60fa95
Add new subsection for signature packs. 2020-12-08 19:54:02 -05:00
fabacab
e9fcf7c620
Add BadBlood. 2020-12-06 15:49:44 -05:00
fabacab
1796f969e6
Add PlumHound. 2020-12-06 15:44:56 -05:00
fabacab
a14164ce30
Add Sigma and YARA to "Threat intelligence" section. 2020-12-06 15:05:06 -05:00
fabacab
127a95bbe4
Add anti-racist messaging. 2020-11-23 13:36:29 -05:00
fabacab
4649860b5e
Add "See also" link to drduh's macOS Security and Privacy Guide. 2020-11-13 15:32:03 -05:00
fabacab
3228974f80
Better description for Santa. 2020-11-13 15:30:17 -05:00
fabacab
30592e81a8
Add PyREBox. 2020-10-25 19:29:48 -04:00
0xACAB
4989f25845
Merge pull request #11 from SpekBin/master
Fixing a typo
2020-10-11 16:00:49 -04:00
Peter Thaleikis
418db3fc24
Fixing a typo 2020-10-11 20:26:48 +04:00
fabacab
81406142fe
Add OneFuzz, Microsoft's now open-sourced Fuzzing-as-a-Service platform. 2020-09-19 15:42:28 -04:00
fabacab
cb77c0eabd
Add Watchtower, a Docker container to update other Docker containers. 2020-09-16 18:24:39 -04:00
fabacab
92bb1b9694
Add Bane, an AppArmor profile generator suited to Docker containers. 2020-08-14 18:07:56 -04:00
fabacab
3b3ff44b6b
Add Trivy. 2020-08-13 22:11:41 -04:00
fabacab
367c468baf
Add Geneva, novel tool for improving availability of blocked content. 2020-08-12 20:57:00 -04:00
fabacab
90fdee8a40
Add "Compliance testing and reporting" section, InSpec, move OpenSCAP. 2020-08-11 00:54:07 -04:00
fabacab
48dd4ba9fb
Add some more app/binary hardening (dynamic binary translation) tools. 2020-07-27 22:45:47 -04:00
fabacab
efbf220953
Add Istio for service-level cloud platform security mention. 2020-07-15 19:52:28 -04:00
fabacab
d0ecbfc3bb
Add container/kernel isolation tools Kata Containers and gVisor. 2020-07-15 19:35:40 -04:00
fabacab
73549f643c
Add Tsunami security scanner. 2020-07-15 18:06:58 -04:00